CWE-24
63 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-24page 1 of 2
- CVE-2014-125033LOWCVSS 3.5EG 7.52023-01-02
A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd…
- CVE-2018-25094LOWCVSS 3.5EG 3.52023-12-03
A vulnerability was found in ระบบบัญชีออนไลน์ Online Accounting System up to 1.4.0 and classified as problematic. This issue affects some unknown processing of the file ckeditor/filemanager/browser/default/i…
- CVE-2019-25087MEDIUMCVSS 5.3EG 7.52022-12-27
A vulnerability was found in RamseyK httpserver. It has been rated as critical. This issue affects the function ResourceHost::getResource of the file src/ResourceHost.cpp of the component URI Handler. The manipulation of the argument uri l…
- CVE-2020-7882HIGHCVSS 7.5EG 7.52021-11-22
Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../')
- CVE-2020-8567MEDIUMCVSS 4.9EG 4.92021-01-21
Kubernetes Secrets Store CSI Driver Vault Plugin prior to v0.0.6, Azure Plugin prior to v0.0.10, and GCP Plugin prior to v0.2.0 allow an attacker who can create specially-crafted SecretProviderClass objects to write to arbitrary file paths…
- CVE-2020-8568MEDIUMCVSS 5.8EG 5.82021-01-21
Kubernetes Secrets Store CSI Driver versions v0.0.15 and v0.0.16 allow an attacker who can modify a SecretProviderClassPodStatus/Status resource the ability to write content to the host filesystem and sync file contents to Kubernetes Secre…
- CVE-2020-9708MEDIUMCVSS 5.9EG 5.92020-08-14
The resolveRepositoryPath function doesn't properly validate user input and a malicious user may traverse to any valid Git repository outside the repoRoot. This issue may lead to unauthorized access of private Git repositories as long as t…
- CVE-2021-21706MEDIUMCVSS 5.3EG 5.32021-10-04
In PHP versions 7.3.x below 7.3.31, 7.4.x below 7.4.24 and 8.0.x below 8.0.11, in Microsoft Windows environment, ZipArchive::extractTo may be tricked into writing a file outside target directory when extracting a ZIP file, thus potentially…
- CVE-2021-26725HIGHCVSS 7.2EG 7.22021-02-22
Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticated administrator to read-protected system files. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3…
- CVE-2021-29466MEDIUMCVSS 6.5EG 6.52021-04-22
Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is able to read local files from the server that can disclose important information. As a workaround, a bot maintainer can…
- CVE-2021-33036HIGHCVSS 8.8EG 8.82022-06-15
In Apache Hadoop 2.2.0 to 2.10.1, 3.0.0-alpha1 to 3.1.4, 3.2.0 to 3.2.2, and 3.3.0 to 3.3.1, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Users should upgrade to Apache Hadoop 2.10.2, 3.2.3, 3.3.2 …
- CVE-2021-3710MEDIUMCVSS 6.5EG 6.52021-10-01
An information disclosure via path traversal was discovered in apport/hookutils.py function read_file(). This issue affects: apport 2.14.1 versions prior to 2.14.1-0ubuntu3.29+esm8; 2.20.1 versions prior to 2.20.1-0ubuntu2.30+esm2; 2.20.9 …
- CVE-2022-1743MEDIUMCVSS 6.8EG 6.82022-06-24
The tested version of Dominion Voting System ImageCast X can be manipulated to cause arbitrary code execution by specially crafted election definition files. An attacker could leverage this vulnerability to spread malicious code to ImageCa…
- CVE-2022-20656MEDIUMCVSS 6.5EG 6.52024-11-15
A vulnerability in the web-based management interface of Cisco PI and Cisco EPNM could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. To exploit this vulnerability, the attacker …
- CVE-2022-29253LOWCVSS 2.7EG 2.72022-05-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting with version 8.3-rc-1 and prior to versions 12.10.3 and 14.0, one can ask for any file located in the classloader using the t…
- CVE-2022-36065HIGHCVSS 7.5EG 7.52022-09-06
GrowthBook is an open-source platform for feature flagging and A/B testing. With some self-hosted configurations in versions prior to 2022-08-29, attackers can register new accounts and upload files to arbitrary directories within the cont…
- CVE-2022-38129CRITICALCVSS 9.8EG 9.82022-08-10
A path traversal vulnerability exists in the com.keysight.tentacle.licensing.LicenseManager.addLicenseFile() method in the Keysight Sensor Management Server (SMS). This allows an unauthenticated remote attacker to upload arbitrary files to…
- CVE-2023-1398MEDIUMCVSS 6.3EG 8.82023-03-14
A vulnerability classified as critical was found in XiaoBingBy TeaCMS 2.0. Affected by this vulnerability is an unknown functionality of the file /admin/upload. The manipulation leads to path traversal: '../filedir'. The attack can be laun…
- CVE-2023-1800HIGHCVSS 7.3EG 7.32023-04-02
A vulnerability, which was classified as critical, has been found in sjqzhang go-fastdfs up to 1.4.3. Affected by this issue is the function upload of the file /group1/uploa of the component File Upload Handler. The manipulation leads to p…
- CVE-2023-20098MEDIUMCVSS 4.4EG 4.42023-05-09
A vulnerability in the CLI of Cisco SDWAN vManage Software could allow an authenticated, local attacker to delete arbitrary files. This vulnerability is due to improper filtering of directory traversal character sequences within system …
- CVE-2023-20166MEDIUMCVSS 6.0EG 6.02023-05-18
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To ex…
- CVE-2023-20167MEDIUMCVSS 6.0EG 6.02023-05-18
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges to root or read arbitrary files. To ex…
- CVE-2023-3056MEDIUMCVSS 4.3EG 4.32023-06-02
A vulnerability was found in YFCMF up to 3.0.4. It has been declared as problematic. This vulnerability affects unknown code of the file index.php. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotel…
- CVE-2023-3057MEDIUMCVSS 4.3EG 4.32023-06-02
A vulnerability was found in YFCMF up to 3.0.4. It has been rated as problematic. This issue affects some unknown processing of the file app/admin/controller/Ajax.php. The manipulation of the argument controllername leads to path traversal…
- CVE-2023-3098MEDIUMCVSS 4.4EG 4.42023-06-05
A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The manipulation leads to path traversal: '../filedir'. Attacking locally is a requirement. Th…
- CVE-2023-3239LOWCVSS 3.5EG 3.52023-06-14
A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the file admin/readDeal.php?mudi=readQrCode. The manipulation of the argument img leads to path traversal: '../filedir'…
- CVE-2023-3240LOWCVSS 3.5EG 3.52023-06-14
A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file usersNews_deal.php. The manipulation of the argument file leads to path traversal: '..…
- CVE-2023-4171MEDIUMCVSS 4.3EG 4.32023-08-05
A vulnerability classified as problematic was found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This vulnerability affects unknown code of the file \Service\FileDownload.ashx. The manipulation of the argument Files l…
- CVE-2023-52076HIGHCVSS 8.5EG 8.52024-01-25
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A path traversal and arbitrary file write vulnerability exists in versions of Atril prior to 1.26.2. This vulnerability is capable of writing a…
- CVE-2023-6699CRITICALCVSS 9.1EG 9.12024-01-11
The WP Compress – Image Optimizer [All-In-One] plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.10.33 via the css parameter. This makes it possible for unauthenticated attackers to read th…
- CVE-2023-6900MEDIUMCVSS 4.6EG 4.62023-12-17
A vulnerability, which was classified as critical, has been found in rmountjoy92 DashMachine 0.5-4. Affected by this issue is some unknown functionality of the file /settings/delete_file. The manipulation of the argument file leads to path…
- CVE-2023-7040MEDIUMCVSS 4.3EG 4.32023-12-21
A vulnerability classified as problematic was found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this vulnerability is an unknown functionality of the file /file-manager/rename.php. The manipulation of the argument oldName leads …
- CVE-2023-7041MEDIUMCVSS 5.4EG 5.42023-12-21
A vulnerability, which was classified as critical, has been found in codelyfe Stupid Simple CMS up to 1.2.4. Affected by this issue is some unknown functionality of the file /file-manager/rename.php. The manipulation of the argument newNam…
- CVE-2023-7058MEDIUMCVSS 6.3EG 6.32023-12-22
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument page leads to path traversal: …
- CVE-2023-7098LOWCVSS 3.1EG 3.12023-12-25
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vulnerability affects unknown code of the file app/hide.php. The manipulation of the argument key leads to path traversal: …
- CVE-2023-7134MEDIUMCVSS 6.3EG 6.32023-12-28
A vulnerability was found in SourceCodester Medicine Tracking System 1.0. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument page leads to path traversal: '../filedir'. The attack ma…
- CVE-2024-0341LOWCVSS 3.5EG 3.52024-01-09
A vulnerability was found in Inis up to 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /app/api/controller/default/File.php of the component GET Request Handler. The manipulation of the argu…
- CVE-2024-0354MEDIUMCVSS 5.3EG 5.32024-01-10
A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to path traversal: '../…
- CVE-2024-0416MEDIUMCVSS 5.4EG 5.42024-01-11
A vulnerability, which was classified as critical, has been found in DeShang DSMall up to 5.0.3. Affected by this issue is some unknown functionality of the file application/home/controller/MemberAuth.php. The manipulation of the argument …
- CVE-2024-0417MEDIUMCVSS 5.4EG 5.42024-01-11
A vulnerability, which was classified as critical, was found in DeShang DSShop up to 2.1.5. This affects an unknown part of the file application/home/controller/MemberAuth.php. The manipulation of the argument member_info leads to path tra…
- CVE-2024-0465LOWCVSS 3.5EG 3.52024-01-12
A vulnerability classified as problematic was found in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file download.php. The manipulation of the argument download_file leads to path tra…
- CVE-2024-0882MEDIUMCVSS 4.3EG 4.32024-01-25
A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the component Universal Download Interface. The manipulati…
- CVE-2024-0989MEDIUMCVSS 5.4EG 5.42024-01-29
A vulnerability, which was classified as problematic, has been found in Sichuan Yougou Technology KuERP up to 1.0.4. Affected by this issue is the function del_sn_db of the file /application/index/controller/Service.php. The manipulation o…
- CVE-2024-10379MEDIUMCVSS 4.3EG 4.32024-10-25
A vulnerability classified as problematic was found in ESAFENET CDG 5. Affected by this vulnerability is the function actionViewDecyptFile of the file /com/esafenet/servlet/client/DecryptApplicationService.java. The manipulation of the arg…
- CVE-2024-12482MEDIUMCVSS 4.3EG 4.32024-12-12
A vulnerability was found in cjbi wetech-cms 1.0/1.1/1.2. It has been rated as problematic. Affected by this issue is the function backup of the file wetech-cms-master\wetech-basic-common\src\main\java\tech\wetech\basic\util\BackupFileUtil…
- CVE-2024-12897MEDIUMCVSS 4.3EG 4.32024-12-23
A vulnerability was found in Intelbras VIP S3020 G2, VIP S4020 G2, VIP S4020 G3 and VIP S4320 G2 up to 20241222. It has been classified as critical. This affects an unknown part of the file ../mtd/Config/Sha1Account1 of the component Web I…
- CVE-2024-1459MEDIUMCVSS 5.3EG 5.32024-02-12
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restr…
- CVE-2024-22079HIGHCVSS 7.5EG 7.52024-03-20
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Directory traversal can occur via the system logs download mechanism.
- CVE-2024-2318MEDIUMCVSS 4.3EG 4.32024-03-08
A vulnerability was found in ZKTeco ZKBio Media 2.0.0_x64_2024-01-29-1028. It has been classified as problematic. Affected is an unknown function of the file /pro/common/download of the component Service Port 9999. The manipulation of the …
- CVE-2024-23657HIGHCVSS 8.8EG 8.82024-08-05
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Nuxt Devtools is missing authentication on the `getTextAssetContent` RPC function which is vulnerable to path traversal. Combined wit…
Map vulnerabilities like CWE-24 to your infrastructure
EchelonGraph correlates every CVE — across CWE-24 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →